Slow Loris Attack - Computerphile

Slow Loris Attack - Computerphile

Computerphile

7 лет назад

1,087,272 Просмотров

Ссылки и html тэги не поддерживаются


Комментарии:

ejonesss
ejonesss - 10.07.2023 15:57

a simple defense analyze the timing of the data.

if it is too slow for the capabilities of even the slowest connection say a 56k line then it comes back with "either upgrade to a faster connection or we will kick your connection and ban you for 10 minutes" or something like that or put a limit to the number of connections say 6

Ответить
Neil Clay
Neil Clay - 23.05.2023 21:26

To come up to date a bit, this is one of the reasons why you find nginx on pretty much every front end of a load balancer these days 😆

Ответить
THE HACKER’S PODCAST
THE HACKER’S PODCAST - 09.05.2023 15:31

Can we get the python script😢

Ответить
Kalinath Katuri
Kalinath Katuri - 26.02.2023 02:26

Randomly ended up here and really enjoyed the demo.

Ответить
John Wick
John Wick - 14.01.2023 01:00

It's funny how simple this is and how it still works lol

Ответить
Puspam Adak
Puspam Adak - 28.12.2022 09:23

Is this Apache vulnerability still valid today? It is far more dangerous than normal DDoS.

Ответить
Alex Kall
Alex Kall - 19.11.2022 22:34

can slowloris work on a public ip address?

Ответить
Novic Cen
Novic Cen - 22.08.2022 14:17

does it still working in apache nowadays?

Ответить
Itumeleng Lesley Ditlhotlhole
Itumeleng Lesley Ditlhotlhole - 12.05.2022 14:49

Really interesting

Ответить
Sebastian Suarez
Sebastian Suarez - 25.03.2022 23:35

I love how excited he is about this DoS and explaining it. The explanation really helped with my studies for CEH! THanks!

Ответить
OficjalnyKrwiopijca
OficjalnyKrwiopijca - 27.02.2022 14:05

I wonder... how many russian propganda media outlets are vulnerable to this attack?
Asking out of pure curiosity, of course... Timing of the question is purely coincidental...

Ответить
Hien Le Thai
Hien Le Thai - 23.02.2022 20:29

So how would I know if my website is being slowloris-ed?

Ответить
ZeldaTheSwordsman
ZeldaTheSwordsman - 10.02.2022 18:06

Dear subtitler: He's saying "Carriage," not "Caret"

Ответить
0yotam
0yotam - 05.01.2022 14:07

ppl still use thread per client in 2022?

Ответить
Léana Jiang
Léana Jiang - 11.12.2021 15:28

This reminds me of endleSSH, which is used to do prevent SSH cracking and wasting hacker’s time

Ответить
BEN
BEN - 29.11.2021 10:12

I don't know how oversimplified is this video, but if someone is actually trying to be secure Idk how he could not think about this possibility

Ответить
Ankit Dubey
Ankit Dubey - 23.11.2021 17:33

you wont let me live , you wont let me die

Ответить
Arkaprabha Chakraborty
Arkaprabha Chakraborty - 18.11.2021 13:03

I thought this video was about Solaris and that the title and thumbnail were just a pun.

Ответить
shiroyasha
shiroyasha - 14.11.2021 18:34

incredible lol

Ответить
Curious Entity
Curious Entity - 12.11.2021 15:51

And that's why you raise your hand before you participate in activities, kids.

Ответить
Abhi Chaurasia
Abhi Chaurasia - 21.10.2021 21:11

This issue should be fixed as more and more servers are using async code.

Ответить
Tommaso Ferroglio
Tommaso Ferroglio - 19.10.2021 17:03

Can it be detected by looking into the simultaneous connection with the same IP?

Ответить
Francisco Eugênio Romanini Nabas
Francisco Eugênio Romanini Nabas - 13.10.2021 20:01

This is an old video, but Mike's videos are lightning my interest on ethical hacking and penetration tests. What courses would you guys recommend? I work with it for more than 15 years now, i'm a System admin with extense knowledge on scripting.
Thank you!

Ответить
Rakesh George
Rakesh George - 11.08.2021 09:16

Why would not the firewall realize that this is an attack? You have 200 connections from the same IP. My guess would be that has something to do with NAT?

Ответить
hackers anonymous
hackers anonymous - 05.08.2021 04:07

My main booter has a slow loris method but it says I need a file path and in parentheses it says (/index.html) what dose that mean and how do I get that.

Ответить
Nilstrieb
Nilstrieb - 31.07.2021 23:29

So this is just another example of proving that async is superiour to multithreaded on IO-bound operations?

Ответить
CZghost
CZghost - 29.07.2021 22:09

This is fairly simple. But one major drawback - servers may catch up by looking at the IP adresses of each concurent connection and if it matches perfectly, they'll cut up all those connections. DDoS has the strength of multiple computers attacking the webserver and the webserver cannot deny each of that attack. Conventional DDoS attacks can be detected and pretty much mitigated by relaying your connection through multiple of caches or simply slowing the connection down a little bit to figure out what's going on. Slow Loris DDoS on the other hand would be kinda undetectable. What if 200 completely random people had painfully slow internet? One way to do this would have a botnet of 200 computers in it trying to access one single website. The other way would be route each connection through Tor (which essentially makes the Tor network your botnet).

Ответить
バンジョベンジ
バンジョベンジ - 25.07.2021 20:17

I think, as computer nerds, we identify with Slow Loris. It's not out there busting down the door guns-blazing. It's using time and ingenuity to win by attrition.

Ответить
Max?
Max? - 24.06.2021 22:54

I've got a question: Why isn't it designed in a way that only a full request can be sent/asked? Like only accept 'Get index.html' and not 'Ge' 't' 'i' 'n' etc.. I don't understand why it starts up a connection/thread when you haven't even asked a full question. Isn't it more simple to let this web-protocol thingy only handle full, finished questions?

Ответить
My mom never gave me a name :/
My mom never gave me a name :/ - 22.06.2021 11:27

British Peter Parker.

Also, what a neat concept!

Ответить
Ngtctf Dcdcf
Ngtctf Dcdcf - 17.06.2021 13:07

And what makes this an original idea while it is alike to the DOS attack in a way? Additionally, many servers don't allow that bad connections and they also close the connection if the packet sent is too small.

Ответить
NaN NaN
NaN NaN - 12.06.2021 22:55

great vid

Ответить
Thinh Le Duc
Thinh Le Duc - 05.06.2021 19:04

who ever created this attack have a brilliance way of thinking XD

Ответить
JayVal90
JayVal90 - 05.05.2021 00:00

So like a Filibuster

Ответить
Mr. Reese
Mr. Reese - 04.05.2021 15:14

I love this and the fact that he also loves it and tries to hide that he loves it makes it even better :D.

Ответить
efs
efs - 04.05.2021 05:32

I just love his evil glee.

Ответить
Eff_Gee
Eff_Gee - 27.04.2021 16:40

The smile on his face when he does the attack

Ответить
Sentient
Sentient - 20.04.2021 09:25

Damn

Ответить
Eoin C
Eoin C - 12.04.2021 02:06

That is just beautifully simple but genius 🔥💯😂

Ответить
Rahul R
Rahul R - 26.03.2021 09:06

OmG.....give a medal to this guy

Ответить
Bald Badger
Bald Badger - 23.03.2021 06:16

A get-around I can think of is not to statically allocate thread count, but to allocate based on server load

Ответить
Димитри Слободяник
Димитри Слободяник - 10.03.2021 10:54

Finally I can hack Google

Ответить
corekid9
corekid9 - 20.02.2021 22:13

nah man, You just have REALLY REALLY REALLY slow 1gb internet

Ответить
Octopus Prime
Octopus Prime - 20.02.2021 22:05

In spirit a lot like a layer 7 version of a tcp-syn attack. Hold the connection open indefinitely.

Ответить
MEMS
MEMS - 11.02.2021 01:31

people with 0.008 mbps internet

i dont even have to try it dose it by it self

Ответить
Tyrrell Davis
Tyrrell Davis - 24.01.2021 20:42

Can we get a code demo of this?

Trying to protect my web servers against all the things

Ответить
Lazergurka - Smerlin
Lazergurka - Smerlin - 12.01.2021 18:51

So, how do you combat this?

Ответить
Adria Martinez
Adria Martinez - 09.01.2021 14:47

But you are sending the CRLF at the end of the random number. I do not understand why

Ответить
Om Khard
Om Khard - 31.12.2020 06:41

best explaination ............ I am blessed to watch a Channel like computerphile, david bombal etc

Ответить
Freddy Palacios
Freddy Palacios - 26.12.2020 02:28

Who knew that learning how to hack would make you a computer coding genius

Ответить